Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 31st, 2007, 06:00 PM
jpcummins jpcummins is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 324
Default Anti-RootKit Software - Your Favorite?

Given the choice of AVG Anti-Rootkit or RootKitRevealer, based on your experience, which one would be your choice. I am using both occasionally but to date AVG is finding nothing while RKR is. This is becoming a bit disconcerting to me. May mean absolutely nothing but I am doubtful. Unfortunately, RKR does not have a manual or guide that helps us, with little experience, to determine what the log is telling us. Fortunately, RKR has a forum for people with little experience and knowledge to seek help from those with this knowledge. I have heard good things about both GMER and Sophos but they both confuse me. And, believe me it doesn't take much to do that. As always I thank you for all your replies.
  #2  
Old December 31st, 2007, 06:12 PM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,624
Default Re: RootKit Software - Your Favorite?

Quote:
Originally Posted by jpcummins
AVG is finding nothing while RKR is.
Are these tests you are running, or real exploits you have been hit with?


----
rich
  #3  
Old December 31st, 2007, 06:23 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: RootKit Software - Your Favorite?

Quote:
AVG is finding nothing while RKR is.
Did you check out the stickies at Sysinternals Forums before you posted there?

Personal recommendation is to look from outside of Windows.
  #4  
Old December 31st, 2007, 06:59 PM
Old Monk's Avatar
Old Monk Old Monk is offline
Frequent Poster
 
Join Date: Feb 2005
Location: Sheffield, UK
Posts: 632
Default Re: RootKit Software - Your Favorite?

Hi

In my limited experience, you have to be a bit careful of anti-rootkit software detectors. Touch nothing while it's scanning for one. Some are very, very sensitive to other software that's hooking the kernel.
__________________
Cheers

Jon
  #5  
Old December 31st, 2007, 11:19 PM
Tarq57's Avatar
Tarq57 Tarq57 is offline
Frequent Poster
 
Join Date: Oct 2006
Location: Wellington NZ
Posts: 966
Default Re: RootKit Software - Your Favorite?

jpc, I'm probably in a similar sort of knowledge area. I've tried Icesword, AVG ARK, Rootkit Revealer, and Sophos. Don't know enough about them- the programs or rootkits in general- to confidently interpret the results.
So I don't.
While learning, the Sysinternals forum proved helpful, and was able to relegate the 2 entries I had to FP's.
My impression of the AVG tool is that it's for the average user, and that RKR is a bit more advanced. Ditto Icesword, and GMER.
My feeling, based on a little reading here and around the W, is that anything designed by Mark Russinovich is likely to be a fairly superior product.
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3.
  #6  
Old December 31st, 2007, 11:49 PM
jpcummins jpcummins is offline
Frequent Poster
 
Join Date: Feb 2006
Posts: 324
Default Re: RootKit Software - Your Favorite?

I should of been more exact in my original posting. What started this is that I had scanned my system with ThreatFire and it detected 2 registry items. I followed that scan with RKR and it found the 2 registry items found by ThreatFire plus 5 others. I then looked with Regedit at the entries found by ThreatFire and RKR and did not see anything suspicious, at least not in my mind. But not relying on my rather limited knowledge I posted the entries found by the two programs to the RKR forum. I received a reply by one of the moderators that addressed each entry and I was told that I had no reason for concern. After all of this I didn't understand why AVG AntiRootKit never detected anything. Either AVG AntiRootKit is such a good program it knew there was not a problem with the entries or perhaps it should of detected the entries and didn't. I just was afraid I was placing too much confidence in the program. Other RootKit postings I have seen has mentioned Sophos, GMER, RootKitRevealer and I believe one or two others but I don't recall seeing AVG AntiRootKit. I guess my question is should I or should I not rely on AVG AntiRootKit? Most likely this is not a yes or no question.
  #7  
Old January 2nd, 2008, 02:36 AM
the Tester's Avatar
the Tester the Tester is offline
Very Frequent Poster
 
Join Date: Jul 2002
Location: The Gateway to the Blue Hills,WI.
Posts: 2,855
Default Re: RootKit Software - Your Favorite?

I would prefer RKR.Especially if their forum has been helpful.
AVG's antirootkit is probably similar to antirootkits from av vendors,designed for ease of use.Don't know about effectiveness though.

I had a site bookmarked that had reviews for antirootkit scanners as well as download links for many scanners.Don't have it anymore and can't find it on a Google Search.
  #8  
Old January 2nd, 2008, 03:15 AM
SystemJunkie SystemJunkie is offline
Resident Conspiracy Theorist
 
Join Date: Mar 2006
Location: Germany
Posts: 1,500
Default Re: RootKit Software - Your Favorite?

Quote:
is that anything designed by Mark Russinovich is likely to be a fairly superior product.
Nearly all, Rootkit Revealer is really outdated and tends to mass fp´s.

Quote:
I have heard good things about both GMER
Yes and you should use it because it is actually nr.1.
  #9  
Old January 2nd, 2008, 04:49 AM
Tarq57's Avatar
Tarq57 Tarq57 is offline
Frequent Poster
 
Join Date: Oct 2006
Location: Wellington NZ
Posts: 966
Default Re: RootKit Software - Your Favorite?

Quote:
I had a site bookmarked that had reviews for antirootkit scanners as well as download links for many scanners.Don't have it anymore and can't find it on a Google Search.
This one?
Quote:
Quote:
I have heard good things about both GMER
Yes and you should use it because it is actually nr.1.
Thanks for the advice.It's one of those applications downloaded a while back that I hadn't followed up on. Now found the online FAQ/help form, let the learning begin!
__________________
Avast Home, MVPS Hostsfile,Secunia PSI Autorun Eater, Windows Firewall, MBAM (demand), XP SP3.
  #10  
Old January 2nd, 2008, 05:52 AM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,433
Default Re: RootKit Software - Your Favorite?

Hello,
Any bootable CD, rootkitty.
Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #11  
Old January 2nd, 2008, 07:35 AM
SystemJunkie SystemJunkie is offline
Resident Conspiracy Theorist
 
Join Date: Mar 2006
Location: Germany
Posts: 1,500
Default Re: RootKit Software - Your Favorite?

@Targ: cool link collection
  #12  
Old January 2nd, 2008, 03:59 PM
jfd15 jfd15 is offline
Frequent Poster
 
Join Date: Oct 2007
Location: Sacramento, CA
Posts: 234
Default Re: RootKit Software - Your Favorite?

any word on Rootkit Unhooker?


i thought this used to be the best, dont know what happened, bought out or something...
  #13  
Old January 2nd, 2008, 04:16 PM
fcukdat's Avatar
fcukdat fcukdat is offline
Malware Researcher
 
Join Date: Feb 2005
Location: England,UK
Posts: 569
Default Re: RootKit Software - Your Favorite?

Quote:
Originally Posted by jfd15
any word on Rootkit Unhooker?


i thought this used to be the best, dont know what happened, bought out or something...

Discontinued
__________________
Ade Gill
Malwarebytes Researcher
  #14  
Old January 2nd, 2008, 05:05 PM
dawgg's Avatar
dawgg dawgg is offline
Frequent Poster
 
Join Date: Jun 2006
Posts: 808
Default Re: RootKit Software - Your Favorite?

IceSword's my personal favorite
... although I haven't had much experience with many rootkits, but I've found it far quicker to remove active rootkits using IceSword than using other tools (in my experience)
  #15  
Old January 2nd, 2008, 11:09 PM
Diver's Avatar
Diver Diver is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: Deep Underwater
Posts: 1,432
Default Re: RootKit Software - Your Favorite?

Personally I prefer Sony. Buy the music and they throw in the root kit for free.
__________________
Only those defenses are good, certain and durable, which depend on yourself alone and your own ability.

The Prince, by Niccolo Machiavelli.
  #16  
Old January 3rd, 2008, 06:47 AM
Maksman's Avatar
Maksman Maksman is offline
Infrequent Poster
 
Join Date: Jan 2008
Location: USA
Posts: 4
Default Re: RootKit Software - Your Favorite?

AKR 2.007 from safe-protect for me, not famous, but very useful..
  #17  
Old January 3rd, 2008, 07:16 PM
jfd15 jfd15 is offline
Frequent Poster
 
Join Date: Oct 2007
Location: Sacramento, CA
Posts: 234
Default Re: RootKit Software - Your Favorite?

Quote:
Originally Posted by fcukdat
Discontinued


come on, they just quit?? no big payday? thats lousy...
  #18  
Old January 4th, 2008, 12:22 AM
G1111's Avatar
G1111 G1111 is offline
Very Frequent Poster
 
Join Date: May 2005
Location: USA
Posts: 1,723
Default Re: RootKit Software - Your Favorite?

Quote:
Originally Posted by jfd15
come on, they just quit?? no big payday? thats lousy...

See December 23, 2007 blog at:
http://www.antirootkit.com/blog/
  #19  
Old January 4th, 2008, 03:49 AM
jfd15 jfd15 is offline
Frequent Poster
 
Join Date: Oct 2007
Location: Sacramento, CA
Posts: 234
Default Re: RootKit Software - Your Favorite?

Quote:
Originally Posted by G1111
See December 23, 2007 blog at:
http://www.antirootkit.com/blog/

thats great...i read some blogger a while back who was trying to say RKU developers were crooked, glad to see thats not true....hope they making a ton of $$$ from Microsoft...that EP_XOFF mentions EASTER and fcukdat for thanks on his site, so there are some people on here who app. really know their stuff
  #20  
Old January 4th, 2008, 03:30 PM
Rasheed187 Rasheed187 is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 1,883
Default Re: Anti-RootKit Software - Your Favorite?

Personally I don´t really have a favorite, but I keep hearing that RkU, IceSword and GMER, are the best. I only use them when my system is acting weirdly and I start to get all paranoid again.

Quote:
Personally I prefer Sony. Buy the music and they throw in the root kit for free.

I see that the topic title has changed, good point.
  #21  
Old January 5th, 2008, 09:29 AM
SystemJunkie SystemJunkie is offline
Resident Conspiracy Theorist
 
Join Date: Mar 2006
Location: Germany
Posts: 1,500
Default Re: Anti-RootKit Software - Your Favorite?

Quote:
any word on Rootkit Unhooker?
Out-of-Date and not finished but still a nice tool of a unique kind, except those massive bsods that can happen.

Some final words to the notorious aggressiveness that RkU Authors had against Gmer (and now they playing down the whole story to distort the truth (remember the sheep and wolf story, first the wolves and suddenly the sheeps?)): One attacks only the one, who owns the ball. So Gmer they only raised the hat to you. I also say "chapeau" for the last revelation of stealth mbr, that is the right direction.

If you get directly/massively attacked no matter in what way then this is a sign that you must be damn good
or/and you must have revealed something deeply hidden that wasn´t intended to be found. (or maybe you woke up a beast from a deep sleep because you brought some rays of light into its darkness;-))

Last edited by SystemJunkie : January 5th, 2008 at 10:05 AM.
  #22  
Old February 3rd, 2008, 03:24 PM
egghead's Avatar
egghead egghead is offline
Frequent Poster
 
Join Date: Aug 2005
Location: The Netherlands
Posts: 439
Default Re: RootKit Software - Your Favorite?

Quote:
Originally Posted by jfd15
any word on Rootkit Unhooker?


i thought this used to be the best, dont know what happened, bought out or something...

It is sold to Microsoft & the development team is going to work for billyboy.

There’s nothing that money can’t buy
  #23  
Old February 3rd, 2008, 03:31 PM
SystemJunkie SystemJunkie is offline
Resident Conspiracy Theorist
 
Join Date: Mar 2006
Location: Germany
Posts: 1,500
Default Re: Anti-RootKit Software - Your Favorite?

Quote:
based on your experience, which one would be your choice.

I show you the toplist based on usefulness, removal and information if system is infected:
(vs ads rootkit, vs fu rootkit, vs fu+hidden)

1. Gmer
2. Radix
3. RkUnhooker
------------------------
4. IceSword
5. McAfee RkDetector
6. AVG
7. Sophos
8. A Tools
9. NIAP Rootkit Detect
10. Blacklight
11. Avira
12. Trend Micro
13. Sysprot
14. Helios
15. Panda
16. RkRevealer

Corrections: 4 tools capable of removing ads streams. IceSword belongs to the top 4.

Last edited by SystemJunkie : February 3rd, 2008 at 05:28 PM.
  #24  
Old February 3rd, 2008, 04:03 PM
fcukdat's Avatar
fcukdat fcukdat is offline
Malware Researcher
 
Join Date: Feb 2005
Location: England,UK
Posts: 569
Default Re: Anti-RootKit Software - Your Favorite?

Quote:
Originally Posted by SystemJunkie
Only 3 tools capable of removing ads streams. A shame otherwise IceSword would be nr.3.

IceSword can whack ADS

Rustock B used for illustration purposes.

Main IceSword GUI select file option.left click on local disk(C: ) to highlight and the right click and select *Enum ADS(include subdir)* option.
Next if you get a suspicious ADS entry you highlight and select copy to bring the binary out of ADS for inspection or alternatively if it is a known badboy then highlight the line and delete

Name:  Rustock ADS.jpg
Views: 458
Size:  13.3 KB
__________________
Ade Gill
Malwarebytes Researcher

Last edited by fcukdat : February 3rd, 2008 at 04:36 PM.
  #25  
Old February 3rd, 2008, 04:34 PM
egghead's Avatar
egghead egghead is offline
Frequent Poster
 
Join Date: Aug 2005
Location: The Netherlands
Posts: 439
Default Re: Anti-RootKit Software - Your Favorite?

just found this one:

http://www.anti-malware-test.com/?q=taxonomy/term/7

anti-malware-test = independent testers at the Russian portal for IT security
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:31 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums